-
Posting on behalf of the person who emailed this question I have a question regarding the CVSS scoring version used by Trivy for classifying the severity levels of CVE vulnerabilities. It appears that Trivy uses CVSS version 2.0, as shown in the example below.
Can you confirm that CVSS version 2.0 is used by Trivy and not CVSS 3.x? Also, if version 2.0 is used by Trivy for the CVE scores and the classification of severity levels, when might Trivy be updated to use CVSS version 3.x? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
The OP was correct - we do currently default to CVSS V2, but we are planning to move to V3 - see aquasecurity/trivy-db#72 |
Beta Was this translation helpful? Give feedback.
The OP was correct - we do currently default to CVSS V2, but we are planning to move to V3 - see aquasecurity/trivy-db#72